Objective:
A security culture is fostered through induction training and
ongoing security education tailored to roles, responsibilities,
changing threat environment and sensitivity of information,
systems and operations
introduce or use unauthorized IT equipment or software on
a system
replace items such as keyboards, pointing devices and
other peripherals with personal equipment
assume the roles and privileges of others
relocate equipment without proper authorization
Agency management is responsible for ensuring that an appropriate information security
awareness and training program is provided to personnel. Without management support, security
personnel might not have sufficient resources to facilitate awareness and training for other
personnel.
Awareness and knowledge degrades over time without ongoing refresher training and updates.
Providing ongoing information security awareness and training will assist in keeping personnel
aware of issues and their responsibilities.
Methods that can be used to continually promote awareness include logon banners, system access
forms and departmental bulletins and memoranda.
Information security awareness and training programs are designed to help system users:
become familiar with their roles and responsibilities
understand any legislative or regulatory mandates and requirements
understand any national or agency policy mandates and requirements
understand and support security requirements
assist in maintaining security
learn how to fulfil their security responsibilities
As part of the guidance provided to system users, there should be sufficient emphasis placed on the
activities that are not allowed on systems. The minimum list of content will also ensure that
personnel are sufficiently exposed to issues that could cause an information security incident
through lack of awareness or through lack of knowledge.
52